Stored Cross-Site Scripting Vulnerability in WP Shortcodes Plugin by WordPress
CVE-2026-3885
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 16 April 2026
What is CVE-2026-3885?
The WP Shortcodes Plugin, specifically the Shortcodes Ultimate version up to 7.4.9, exposes users to Stored Cross-Site Scripting due to inadequate input sanitization and output escaping on attributes passed to the 'su_box' shortcode. This vulnerability allows authenticated attackers with contributor-level access and higher to inject arbitrary web scripts into pages, enabling the scripts to execute automatically when users view the compromised pages.
Affected Version(s)
WP Shortcodes Plugin β Shortcodes Ultimate 0 <= 7.4.9